CVE-2026-69247 is a side-channel vulnerability in pyca/cryptography versions 44.0.0 through 49.9.9 affecting pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime. During processing of a PKCS#7 RecipientInfo encryptedKey, RSA PKCS#1 v1.5 decryption outcomes were exposed through distinguishable exceptions, recovered-key-length disclosure, and timing differences. Invalid RSA padding, a decrypted value of an invalid key length, a correctly sized but incorrect key that later fails AES-CBC/PKCS#7 processing, and a valid key follow observably different paths. This creates a Bleichenbacher oracle against the content-encryption key when application behavior reflects those distinctions to an attacker.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cryptographic side-channel vulnerability in python313-cryptography's PKCS#7 EnvelopedData decryption that exposes a Bleichenbacher oracle via distinguishable error behavior and timing.
A network-reachable confidentiality-impact vulnerability affecting the Fedora 44 pyOpenSSL, python-cryptography, and python-pynitrokey packages. The provided CVSS v3 vector rates attack complexity as high and confidentiality impact as high.
A vulnerability in the pyca/cryptography package's PKCS#7 EnvelopedData decryption logic that exposes a Bleichenbacher-style oracle via distinguishable errors and timing differences, potentially allowing recovery of the content-encryption key in services that decrypt attacker-supplied EnvelopedData.
A Bleichenbacher timing/error oracle vulnerability in pyca/cryptography PKCS#7 decryption that can allow remote attackers to recover RSA-wrapped content encryption keys and decrypt S/MIME or other PKCS#7-encrypted data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.